Business Release Lead · CIBC · Toronto, Ontario

I write the requirement, run the release, then go build the thing myself.

At CIBC I own the pilot and verification process for a monthly consumer digital banking release, and I wrote the runbook that defines it. Outside the bank, I build: two live applications, two ecosystems, both test-covered.

Availability Open to new roles — Toronto, hybrid, remote, or relocating.
Sohaib Zaheer
Current role Business Release Lead, CIBC
Release cadence Monthly · 2-week pilot · 2 regions
Caught before production 2–3 defects per release
Shipped and public 2 live apps, 2 ecosystems
The business half

Four years, four roles, one direction

Each move went closer to the release, and then closer to the build.

Role 01

Sr. Consultant, Digital Agile Operations — Business Release Lead

CIBC · Toronto · May 2024 – Present Promoted from Consultant, Nov 2025
  • Wrote the runbook that defines pilot and post-implementation verification for the release train — an eight-stage lifecycle with templates for planning, communications, status reporting, sign-off and exception handling.
  • Chair the go / no-go decision points on release weekend, coordinating feature product owners, a technology release lead and an external testing vendor across a release train of up to 12 people.
  • Built a two-day buffer between the schedule communicated to stakeholders and the true internal deadline, so a late partner doesn't move the release.
Role 02

IT Project Coordinator

CIBC · Toronto · Sept 2023 – May 2024
  • Standardised JIRA intake templates for incoming requests, which improved both review time and turnaround time for the team taking them.
  • Coordinated 10+ cross-functional stakeholders through delivery ceremonies, keeping one written record of decisions rather than a thread per person.
Role 03

Treasury Data Operations Analyst

CIBC · Toronto · May – Aug 2023
  • Ran a twice-daily reporting cycle for a four-month term, modelling the data in Oracle through TOAD and SQL and reporting it in Excel — the same figures, on time, twice a day.
  • Rebuilt the repeated steps of that cycle into a fixed sequence, so the second run of the day was a checklist rather than a re-derivation.
Role 04

Risk Analyst

CIBC · Toronto · Sept 2022 – Apr 2023
  • The entry point into the bank, and the start of four years spent moving toward the release and then toward the build.
The build half

Selected work

Two applications, two ecosystems. Both live, both public, both with test suites and automated deploys.

Work 01

Tadabbur

Shipped

A Quranic Arabic learning app. A curriculum path, a lesson player, an SM-2 spaced-repetition engine, and prayer-time calculation that runs on the device.

Flutter · Dart · Supabase · PWA
Decision

Ships to the home screen rather than the app stores. No review cycle, no developer account, and one release process instead of three.

106 commits · 17 test files across 55 source files · 49 migrations · CI runs static analysis, the full test suite and deployability checks before anything reaches the live site
Tadabbur lesson player: a reading passage from Al-Fatiha in full Tashkeel with transliteration and translation
Lesson player — reading passage, full Tashkeel
Work 02

Kusuo

Shipped Refused by design

A local-first personal growth app. No backend, no accounts, no telemetry and no gamification — and a PRODUCT.md that explains why each of those is absent.

React 19 · TypeScript · Vite · Dexie / IndexedDB
Decision

An append-only event log, written only by the iPhone. Un-ticking a habit is recorded rather than erased, and a second writer, if one is ever added, merges as a set union.

48 commits · 30 unit test files · 4 Playwright end-to-end suites, including offline and viewport-scaling coverage
Kusuo today view on a phone: two of five habits ticked, a 13-day Fajr streak, the week strip, and a training session nine of seventeen sets in
Today — habits and the day's session
Email me about a role Or read how either one was built.
The through-line

Both halves are the same instinct: catching problems before they reach a person

I did the business diploma first and the IT degree second. The order is why I read a requirement before I read a ticket.

I put the slack in the schedule, not in the plan

The date stakeholders work to is two days ahead of the true internal deadline. A late partner costs the buffer instead of the release.

Escalation needs evidence

Defects raised during pilot go through a structured reproduction checklist before they escalate, so the conversation starts with steps rather than opinions.

If it can't be piloted, it needs a written reason

The exception path is formal: written justification, a remediation plan, and approval. The cost of skipping verification stays visible instead of quiet.

The gate runs before the person does

In my own work that means CI gates, offline tests, and an append-only event log that keeps any future merge a set union by ID. At the bank it means a pilot phase that surfaces two to three defects per release.

Full depth

Case studies

Written, not claimed

Writing & documentation

Published guide
iFixit Guide 136964 Revised against the iFixit team's feedback and hosted on their domain rather than mine.
ifixit.com ↗
Product document
Kusuo — PRODUCT.md The argument for what the app leaves out: no backend, no accounts, no telemetry, no gamification.
github.com ↗
Product & architecture
Tadabbur — product and architecture documents Requirements include screen-reader support, adjustable text size and colour-blind-safe coding, written before the build.
github.com ↗
Runbook
Pilot and post-implementation verification runbook Eight stages, with templates for planning, communications, status reporting, sign-off and exception handling. Internal to the bank — described here in industry-standard terms only.
Not publishable
Where each one was used

Skills

Business & delivery

Release management, pilot and verification planning, go / no-go facilitation, defect intake and triage, exception handling, stakeholder communications, JIRA, Agile ceremonies.

Used on the consumer digital banking release train — monthly, across web, iOS and Android.

Analysis & data

SQL, Oracle via TOAD, Excel reporting, data cleaning, descriptive statistics, visualization, MATLAB.

Used on a twice-daily Treasury reporting cycle, and on a heart-failure dataset analysis at York.

Build

Flutter, Dart, React 19, TypeScript, Vite, Supabase, Dexie / IndexedDB, PWA delivery, spaced-repetition scheduling, unit testing, Playwright, CI pipelines.

Used to ship Tadabbur and Kusuo — both live, both public.

Tools

Git, GitHub Actions, JIRA, TOAD, Excel, Figma, VS Code.

Used daily, on both halves of the work.

Secondary

Also built

Also 01
Heart-failure dataset analysis, MATLAB Built
Data cleaning, descriptive statistics and visualization. Coursework, York University.
Also 02
Haru Prototype
A prototype. Never published, and listed here as one.
Also 03
Engagement RSVP site Shipped
A passion project. Shipped to real guests against a date that could not move.
Also 04
Scentwise Redeploying
Live site — unavailable
Education

Education

Bachelor of Arts (Honours), Information Technology York University · 2019–2024
Business Administration Diploma Humber College · 2017–2018

Two minutes is enough

The subject line is pre-filled, so the next thing you do is type rather than decide how to start.

Open to new roles — Toronto, hybrid, remote, or relocating.